A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://github.com/HashBrownCMS/hashbrown-cms/issues/327 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T09:18:02.522Z
Reserved: 2020-01-13T00:00:00
Link: CVE-2020-6949

No data.

Status : Modified
Published: 2020-01-13T19:15:12.930
Modified: 2024-11-21T05:36:22.553
Link: CVE-2020-6949

No data.

No data.